- Documentation
- /
- Area
- /
- 00 — Overview
00 — Overview
Queensland Audit Office (QAO) reference application. This is a demonstration prototype modelled on the Queensland Audit Office's public-facing documentation, reports, guidance and activities. It is not an official QAO system and holds no real audit information — every entity, report, recommendation and decision in the demo data is fictional and illustrates the data model and workflow only.
What AREA is
The Audit Recommendation & Evidence Assurance Manager turns the follow-through on audit recommendations into a structured, evidence-backed register. A recommendation is not "done" because someone says so — it is done when the committed actions are complete, the mandatory evidence has been submitted and independently validated as sufficient, there are no open blocking exceptions, and an authorised approver has signed the closure. AREA holds every one of those links so the state of assurance is always demonstrable.
The domain
Public-sector audit offices issue recommendations; agencies respond, act, and gather evidence; someone independent must confirm the evidence actually demonstrates the commitment before the recommendation can be closed. The hard parts are provenance (which evidence proves which requirement), independence (validation separate from the doer), and closure discipline (no closing over an unresolved blocking exception). AREA models all three.
The 16 models by area
Audit Register (4) - Entity — the audited organisation (department, agency, statutory body). - AuditReport — the tabled report a recommendation comes from. - Recommendation — the central record; carries status, priority and assurance status. - StatusHistory — the lifecycle trail of a recommendation.
Responses & Actions (3) - ManagementResponse — the entity's position (accept / partial / do-not-accept), versioned. - ImplementationAction — a committed action delivering the recommendation. - Milestone — a checkpoint within an action.
Evidence & Validation (4) - EvidenceRequirement — what evidence is required (and whether it is mandatory). - EvidenceSubmission — the evidence actually provided (with document URI, checksum, supersession). - ValidationTest — a reusable test/method for judging evidence sufficiency. - EvidenceValidation — an independent validation applying a test to submitted evidence, with an outcome.
Assurance & Closure (5) - Exception — a gap or deficiency; may be closure-blocking. - Risk — the risk arising from a recommendation/exception (inherent & residual scored). - AssuranceDecision — an authorised decision (e.g. defer, accept, treat). - ClosureRequest — a request to close, declaring completion. - ClosureApproval — the authorised approve / reject / defer outcome.
(The source pack's DomainEvent outbox is Phase 2 — see page 03.)
The demo scenario
A QAO-style performance audit of major ICT project delivery at the Department of Transport & Main Roads, report QAO-2026-14, with two recommendations:
- Recommendation 1 — Strengthen ICT project governance. Accepted → two actions completed (framework issued, boards trained) → evidence submitted and independently validated SUFFICIENT → closure requested and APPROVED → CLOSED.
- Recommendation 2 — Improve benefits realisation tracking. Partially accepted → one action in progress → interim evidence validated INSUFFICIENT → an open blocking exception with an attached risk and an assurance decision to defer → sits at EXCEPTION_OPEN.
35 rows across all 16 models — enough to show the whole spine in both a "closed clean" and a "blocked" state.